Skip to main content
Category: Contracting & Acquisition

Defense Federal Acquisition Regulation Supplement

Also known as: DFARS, DFARS, Defense Federal Acquisition Regulation Supplement
Simply put

The DFARS is a set of rules the Department of Defense (DoD) uses to guide how it buys goods and services. It adds defense-specific requirements on top of the government-wide Federal Acquisition Regulation (FAR). In practice, it tells DoD components and their contractors what additional policies and procedures apply to defense contracts.

Formal definition

The Defense Federal Acquisition Regulation Supplement (DFARS) is maintained by the Defense Acquisition Regulations System within DoD and provides uniform acquisition policies and procedures that supplement the FAR for the Department of Defense. It contains requirements of law, DoD-wide policies, delegations of FAR authorities, deviations from FAR requirements, and related implementing guidance; as used in the DFARS, 'departments and agencies' refers to the military departments and the defense agencies. The DFARS is accompanied by companion Procedures, Guidance, and Information (PGI) that supports internal DoD acquisition procedures. Practitioners should distinguish the DFARS as an acquisition regulation from specific cybersecurity-related clauses implemented through it, and should verify the current text of any subpart or clause against the official DFARS, as content changes across revisions and rulemakings.

Why it matters

The DFARS is the primary vehicle through which the Department of Defense translates statutory requirements, DoD-wide policies, and defense-specific priorities into binding acquisition terms. Because it supplements the government-wide Federal Acquisition Regulation (FAR) rather than replacing it, any organization doing business with DoD components is generally subject to both the FAR and the applicable DFARS provisions. Misunderstanding this layered relationship is a common and costly error: a contractor familiar with civilian agency contracting under the FAR cannot assume those terms fully describe its obligations on a defense contract, because the DFARS may add, delegate, or deviate from FAR requirements.

For compliance officers and contracting professionals, the DFARS matters because it is the mechanism that implements many defense-specific obligations, including cybersecurity-related clauses. An expert would caution against conflating the DFARS as an acquisition regulation with the individual clauses implemented through it; the regulation is the framework, while specific subparts and clauses carry the detailed requirements. Treating the DFARS as static is another frequent mistake, as its content changes across revisions and rulemakings published through the Federal Register, and relying on an outdated subpart can lead to noncompliance.

Because the DFARS carries requirements of law and DoD-wide policy, its provisions can have direct contractual and legal consequences. Practitioners should verify the current text of any subpart or clause against the official DFARS and its companion Procedures, Guidance, and Information (PGI) rather than relying on summaries, and should confirm which provisions apply to a given contract, as this entry does not cover the contractual or legal specifics of any individual clause.

Who it's relevant to

Defense Contractors and Subcontractors
Organizations selling goods or services to DoD are generally subject to applicable DFARS provisions in addition to the government-wide FAR. Contractors should identify which DFARS subparts and clauses apply to their specific contracts and verify the current text, since the DFARS may add, delegate, or deviate from FAR requirements. This entry does not cover the contractual specifics that a contractor must confirm against the official DFARS.
Contracting Officers and Acquisition Professionals
Personnel within the military departments and defense agencies rely on the DFARS and its companion PGI for uniform acquisition policies and procedures. Because the DFARS implements requirements of law and DoD-wide policy and changes across revisions, acquisition professionals should work from the current official text when structuring and administering defense contracts.
Compliance Officers and Auditors
Those responsible for verifying contractual compliance should treat the DFARS as the framework through which many defense-specific obligations, including cybersecurity-related clauses, are implemented. An expert would emphasize distinguishing the DFARS as an acquisition regulation from the individual clauses carried within it, and confirming that any cited subpart or clause reflects the current rulemaking rather than a superseded version.
Legal and Contracts Counsel
Because DFARS provisions can carry requirements of law and direct contractual consequences, counsel supporting defense contracting should verify the applicable current provisions against the official DFARS and Federal Register rulemakings. Legal interpretation of any specific clause is outside the scope of this entry and should be confirmed against authoritative sources.

Inside DFARS

Defense Federal Acquisition Regulation Supplement (DFARS)
The Department of Defense supplement to the Federal Acquisition Regulation (FAR), issued and maintained by DoD to implement and add to FAR requirements for defense acquisitions. It applies to DoD contracts and does not by itself govern civilian agency acquisitions, which follow the FAR and any agency-specific supplements.
DFARS Clause 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
A widely referenced clause that generally requires contractors handling covered defense information to provide adequate security and to report cyber incidents. It is commonly associated with the safeguarding of Controlled Unclassified Information (CUI) in the defense context. Practitioners should verify current clause text and applicability against the authoritative source.
Relationship to NIST SP 800-171
DFARS safeguarding requirements are frequently tied to the protection of CUI in nonfederal systems, for which NIST SP 800-171 provides the security requirements. The clause and the NIST publication are distinct instruments: DFARS is a contractual/acquisition regulation issued by DoD, while SP 800-171 is a control set maintained by NIST. Applicable revisions may change over time.
Cyber incident reporting obligations
Certain DFARS clauses impose obligations to report cyber incidents to DoD within specified conditions and timeframes. The precise reporting mechanics, thresholds, and timelines should be confirmed against the current clause text rather than assumed.
Scope boundary from CMMC and other authorities
DFARS clauses and the Cybersecurity Maturity Model Certification (CMMC) program are related but distinct. DFARS is the acquisition regulation supplement; CMMC is a separate DoD assessment and certification construct with its own phased rollout and revisions. Neither should be treated as interchangeable with the other.

Common questions

Answers to the questions practitioners most commonly ask about DFARS.

Does DFARS clause 252.204-7012 mean the same thing as CMMC?
No. DFARS clause 252.204-7012 and CMMC are distinct, though related. The DFARS safeguarding clause generally requires contractors handling covered defense information to implement the security requirements in NIST SP 800-171 and to report cyber incidents. CMMC is a separate DoD program intended to add third-party or self-assessment verification of those and related requirements. Conflating the two is a common error; the clause establishes a contractual safeguarding and reporting obligation, while CMMC addresses how conformance is assessed. Verify the current relationship between the two against official DoD and DFARS sources, as CMMC has been rolled out and revised in phases.
If a cloud service is FedRAMP authorized, does that automatically satisfy DFARS requirements?
Not automatically. FedRAMP authorization and DFARS obligations are separate. FedRAMP is an authorization program primarily oriented toward federal civilian cloud use, while DFARS safeguarding provisions impose contractual requirements on defense contractors, and DoD applies its own cloud requirements and impact levels. A FedRAMP authorization may be relevant evidence, but it does not by itself demonstrate that a contractor has met the specific DFARS safeguarding, incident reporting, or cloud-related conditions. Confirm the applicable requirements against current DoD and contract-specific terms.
Which contracts does the DFARS safeguarding clause apply to, and how do I know it applies to mine?
As a general matter, the DFARS applies to acquisitions by the Department of Defense, and safeguarding provisions are typically incorporated into applicable contracts and solicitations. Whether a specific clause flows down to your organization depends on the contract terms and the nature of the information handled, such as covered defense information or Controlled Unclassified Information. Because applicability is driven by contract language rather than assumption, review the actual clauses in your award and consult your contracting officer to confirm current requirements.
What does DFARS-driven implementation of NIST SP 800-171 generally involve?
In most implementations, meeting the DFARS safeguarding expectation involves implementing the security requirements described in NIST SP 800-171 for the applicable revision, documenting the environment where covered information is processed or stored, and addressing gaps through mechanisms such as a system security plan and associated plans of action. The specific controls, scoring approach, and documentation expectations depend on the governing revision and contract terms, so confirm the current NIST SP 800-171 revision and any DoD assessment expectations against authoritative sources.
What are the incident reporting obligations under the DFARS safeguarding clause?
The safeguarding clause generally requires contractors to report covered cyber incidents to the Department of Defense within the timeframe and through the channels specified in the clause. Reporting obligations may also involve preserving relevant information and cooperating with follow-on activity. Because the precise triggers, timelines, and submission methods are set by the clause text and DoD guidance and may change, do not rely on general descriptions; verify the exact reporting requirements in the current clause language applicable to your contract.
How does compliance with the DFARS safeguarding clause relate to actual security?
Meeting the DFARS safeguarding requirements is a contractual and compliance obligation, not a guarantee of security. Implementing the referenced controls establishes a baseline, but effective protection of covered information also depends on continuous monitoring, timely remediation, and operational practices beyond documented compliance. Treating a completed assessment or documentation package as equivalent to being secure is a common mistake; compliance status and security posture should be maintained and validated on an ongoing basis. This entry does not address the legal or contractual consequences of noncompliance, which should be confirmed with appropriate counsel and your contracting officer.

Common misconceptions

DFARS and the FAR are the same thing, or DFARS applies government-wide.
DFARS is DoD's supplement to the FAR and applies to defense acquisitions. Civilian agencies operate under the FAR and their own agency supplements, so DFARS requirements do not automatically extend to non-DoD contracts.
Meeting DFARS clause 252.204-7012 is the same as being CMMC certified.
The DFARS safeguarding clause and CMMC are distinct instruments. Compliance with a contractual safeguarding clause does not by itself constitute a CMMC certification, and CMMC has its own separate phased rollout and revisions that should be verified against current DoD guidance.
DFARS clause 252.204-7012 and NIST SP 800-171 are one and the same requirement.
DFARS is a contractual acquisition regulation issued by DoD, while NIST SP 800-171 is a security requirements set maintained by NIST. The clause commonly references the NIST controls for protecting CUI, but they are separate documents maintained by different bodies and revised on their own cycles.

Best practices

Confirm which specific DFARS clauses are incorporated into your contract, and read the current authoritative clause text rather than relying on summaries, since clause content can change across revisions.
Verify whether covered defense information or CUI is actually present in your systems before scoping safeguarding obligations, and treat DFARS applicability as contract-specific.
Distinguish DFARS contractual requirements from the associated NIST SP 800-171 control set, and track the applicable revision of each independently.
Do not assume DFARS compliance equates to CMMC certification; confirm CMMC status and requirements separately against current DoD guidance and its phased rollout.
Establish and test cyber incident reporting procedures aligned to the timeframes and conditions in the applicable clause text, verifying the current reporting mechanics against official sources.
Consult contracting and legal counsel to confirm contractual, implementation, and scope specifics, since DFARS entries here do not cover contract-specific or legal determinations.